Detection and Containment Flashcards
The OODA Loop is a decision-making model created to help responders think
clearly during the “fog of war”
OODA Loop
OODA Loop
Observe
Orient
Decide
Act
Observe
Observe
Involves reflecting on what has been found during observations and considering
what should be done next
Orient
Makes suggestions towards an action or response plan while taking into
consideration all of the potential outcomes
Decide
Carry out the decision and related changes that need to be made in response to
the decision
Act
Defensive Capabilities
Detect
Destroy
Degrade
Disrupt
Deny
Deceive
Identify the presence of an adversary and the resources at their
disposal
Detect
Render an adversary’s resources permanently useless or ineffective
Destroy
Reduce an adversary’s capabilities or functionality, perhaps temporarily
Degrade
Interrupt an adversary’s communications or frustrate or confuse their
efforts
Disrupt
Prevent an adversary from learning about your capabilities or accessing
your information assets
Deny
Supply false information to distort the adversary’s understanding and
awareness
Deceive
Determine if an incident has taken place, triage it, and notify relevant
stakeholders
Detection and Analysis
Triage and categorization are done based on an impact-based or taxonomy-based
approach
Impact-based Approach
Taxonomy-based Approach